CVE-2016-0174 is an Elevation of Privilege vulnerability affecting the kernel-mode drivers in various Microsoft Windows versions, including Vista, 7, 8.1, 10, and Server editions. A local attacker can exploit this flaw by running a specially crafted application to gain elevated privileges on the system. This vulnerability has a high CVSS score of 7.8, indicating a significant risk, as it allows for complete compromise of confidentiality, integrity, and availability once exploited. The attack requires local access but is low complexity, meaning it can be executed relatively easily. Currently, there is no public exploit code available in common repositories like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are also minimal, suggesting it has not garnered widespread attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.